CYBERSECURITYTRACKER
TRACKING8,154 stories in this site build1,811 vulnerability news stories in this site build

State now. Changed: +93 tier promotions, 0 known-exploited vulnerability additions, 75 leak-site claims, and 2 confirmed breaches since yesterday.

Why today matters ·Today

News

The latest security reporting, combined across sources and tagged, newest first.

Reporting is aggregated from multiple sources. Anything Cybersecurity Tracker computes or infers is labelled as its own judgment, never as a claim made by a source. Stories are combined, de-duplicated, and tagged by category, vendor, and threat actor. Filter by your job role, follow the vendors you run, get the email digest, or subscribe by Really Simple Syndication (RSS). No account required.

Why now: this site build contains 8,154 stories, with the newest available reporting below.

Browse latest storiesSkip to latest stories
Filter by role (optional)

Showing: All categories

Details

Latest stories, newest first

Loading feed…
ai security

Anthropic Prospectus Reveals Surging Sales, Worsening Losses

Source: HealthcareInfoSecurity.

Anthropic's prospectus filing reveals that sales through Amazon and Google marketplaces accounted for 47% of the frontier artificial intelligence (AI) lab's 2025 revenue, with Claude generating rapid growth. The company faces mounting financial pressures from soaring compute costs, customer concentration risk, and massive infrastructure commitments that outpace revenue gains.

Why it matters: Security practitioners evaluating AI vendor stability and supply chain risk should assess Anthropic's dependence on cloud hyperscalers and rising cash burn as potential indicators of service continuity or pricing pressure.

Tracker inference

breaches incidents

Poland Probes Hack of Second Health Software Vendor

Source: HealthcareInfoSecurity.

Polish authorities are investigating a cyberattack on healthcare software vendor Qbusoft affecting its Medyc product, which may have exposed up to 5 million patient medical records. The same threat actor appears responsible for a recent breach of MyDr that compromised records of 19 million Polish patients.

Why it matters: Polish healthcare providers and patients face compounded exposure as a single threat actor targets multiple medical software platforms, creating a systemic risk to national healthcare data security and requiring vendors to assess their own compromises.

Tracker inference

threat intel

'The Art of War' Never Said Know Only Your Vulnerabilities

Source: HealthcareInfoSecurity.

The article argues that identifying vulnerabilities alone is insufficient for security strategy without understanding adversary intent and business context. Strategic threat intelligence integrates attacker behavior with organizational risk to establish meaningful security priorities.

Why it matters: Security teams relying solely on vulnerability lists lack the adversary intent data needed to allocate defenses effectively against real threats to their business.

Tracker inference

ai security

Irony alert: OpenAI whines that Chinese model stole its special IP that it stole from everybody else

Source: The Register Security.

OpenAI disclosed that individuals linked to China's Moonshot artificial intelligence (AI) conducted a distillation attack from July 1 through July 28, 2026, sending thousands of coordinated queries to extract reasoning capabilities from OpenAI's models without breaching encryption or databases. The attack involved manipulating model interactions across over 15,000 user accounts to reproduce protected outputs in visible forms, violating OpenAI's terms of service. OpenAI disrupted the campaign, implemented account bans and infrastructure controls, and shared investigation details with other artificial intelligence (AI) firms and government programs.

Why it matters: Practitioners securing artificial intelligence (AI) deployments must monitor for adversarial distillation attacks that extract model capabilities at scale to train rival systems without safety guardrails, a threat now confirmed as active and sophisticated by state-linked actors.

Tracker inference

cloud saas

Automakers routinely share personally identifiable connected-car data with third parties, report says

Source: The Record.

A recent study documents how automakers share personally identifiable information from connected vehicles with third parties in the advertising ecosystem, exposing drivers to a broader network of corporations. The practice reveals privacy risks inherent in the data collection and monetization practices of vehicle manufacturers.

Why it matters: Vehicle owners and security teams responsible for fleet management should understand that connected car data flows to advertisers and data brokers without clear driver consent, creating privacy and potential security exposures.

Tracker inference

vulnerabilities

DIVD says Zammad zero-days enabled AI-driven network breach

Source: BleepingComputer.

The Dutch Institute for Vulnerability Disclosure (DIVD) disclosed that attackers compromised its internal network by chaining two previously unknown flaws in the Zammad open-source ticketing platform. The organization's breach demonstrates how dependent organizations are on widely deployed software with unpatched security gaps.

Why it matters: Security teams running Zammad should urgently assess their instances for exploitation; organizations relying on ticketing systems for credential and sensitive data handling face exposure until patches are available.

Tracker inference

government policy

After reports on suicide deaths, Pentagon puts Cyber Command on notice

Source: The Record.

The Pentagon's assistant secretary for cyber policy issued demands to U.S. Cyber Command leadership following reports of multiple suicide deaths among personnel, as detailed in an August 31 memo obtained by Recorded Future News.

Why it matters: Cyber Command and DoD personnel should track internal policy directives and wellness initiatives resulting from this review, as they may affect personnel management and operational readiness.

Tracker inference

breaches incidents

Hackers stole millions of US military personnel records during months-long data breach

Source: TechCrunch Security.

The Department of Defense disclosed a months-long data breach affecting millions of current and former U.S. military personnel, with personal information stolen during the incident. The notification covered an extended compromise period before detection and remediation.

Why it matters: Military personnel and veterans face identity theft, social engineering, and targeting risks; security teams should prepare for potential credential exposure and monitor for related fraud or exploitation.

Tracker inference

vulnerabilities

Google: Vulnerability disclosures double to 10,000 per month as AI fuels exploitation

Source: The Record.

Vulnerability disclosures have reached 10,000 per month, representing a doubling in volume over the course of the year, according to Google researchers. The surge is attributed to artificial intelligence (AI) accelerating exploitation and discovery capabilities.

Why it matters: Security teams must accelerate patching and triage processes as the vulnerability pipeline grows exponentially; organizations risk falling further behind attack surface management.

Tracker inference

ai security

As AI Reshapes the SOC Career Ladder, Satisfaction Rises for 91%, but Entry Gets Harder for Nearly Half

Source: Dark Reading.

Research from Swimlane reveals that 91% of security operations center (SOC) staff report higher job satisfaction as artificial intelligence (AI) reshapes career progression, yet nearly half of entry-level candidates face increased barriers to joining the field. The data highlights a tension: while AI-driven detection and response strengthens defensive capabilities, 25% of security professionals worry that automation limits their skill development opportunities.

Why it matters: Security leaders and practitioners need to address the skill development gap created by AI automation in SOCs, as talent pipeline constraints at entry level and mid-career stagnation could undermine long-term defensive capability.

Tracker inference

vulnerabilities

16-year-old researcher found a Microsoft bug, got admin access to databases with 17.3 trillion rows

Source: The Register Security.

A 16-year-old researcher exploited an unsigned JSON Web Token validation flaw in Microsoft's internal Titan analytics service to gain administrator access and query databases containing approximately 17.3 trillion rows. The researcher, using an artificial intelligence (AI)-powered tool called Antares, discovered that Titan's authentication logic checked token contents but never verified the cryptographic signature, allowing him to assume admin privileges. Microsoft patched the vulnerability and awarded a $5,000 bounty after coordinated disclosure.

Why it matters: Organizations building authentication systems must verify token signatures as a critical control; this researcher demonstrates how skipping that check nullifies all downstream access controls and exposes sensitive internal data at scale.

Tracker inference

ai securityResearch

Attackers Are Now Stealing AI Models, Prompts, and API Keys

Source: Halcyon.

Stolen artificial intelligence (AI) model listings, prompt libraries, and application programming interfaces (API) keys have surged on underground markets from under 50 per month to over 1,400. The article examines how this illicit trade operates and the mechanics behind these thefts.

Why it matters: Organizations using AI services face exposure of proprietary models, sensitive prompts, and credentials that could enable unauthorized access to APIs and breach of intellectual property.

Tracker inference

breaches incidents

Over 543,000 valid credentials exposed in public GitHub repositories

Source: BleepingComputer.

Over 543,000 valid credentials discovered in public GitHub repositories remained active as of July, indicating that GitHub's built-in protections against accidental exposure of sensitive data did not prevent these leaks. The scale and persistence of exposed credentials across public code repositories demonstrates a widespread risk to organizations relying on the platform.

Why it matters: Development teams and security practitioners must audit their GitHub repositories and secrets management practices immediately, as exposed credentials can grant attackers direct access to production systems, cloud accounts, and third-party services.

Tracker inference

breaches incidents

Radford experiencing outage after potential data incident

Source: DataBreaches.net.

The City of Radford announced an internet outage following a potential data breach. City leadership engaged cybersecurity professionals and legal counsel upon discovery and notified state and federal law enforcement.

Why it matters: Municipal government employees and residents of Radford face service disruption and potential personal data exposure; practitioners should monitor for indicators of compromise and assess whether similar vulnerabilities exist in their own critical infrastructure.

Tracker inference

vulnerabilitiesTracker priority: TrackCVE-2026-102489CVE-2026-102490

NCSC-2026-0396 [1.00] [H/H] Kwetsbaarheden aangetroffen in Zammad

Source: NCSC Netherlands Advisories.

Two zero-day vulnerabilities were discovered in Zammad. CVE-2026-102489 allows an unauthenticated attacker to execute arbitrary code remotely on versions 6.3.0 through 6.5.4, while CVE-2026-102490 enables a low-privilege user to escalate to root access on all current Zammad versions. Both vulnerabilities have been actively exploited since September 21, 2026 to gain root access on affected systems.

Why it matters: Organizations running Zammad are at immediate risk of remote code execution and privilege escalation; patching or upgrading to a version above 6.5.4 is critical given active exploitation.

Tracker inference

vulnerabilitiesResearchTracker priority: TrackCVE-2026-19445

CPython [CVE-2026-19445] Use-after-free of a server-side SSLContext when sni_callback switches contexts

Source: oss-security.

CPython contains a critical use-after-free vulnerability in the server-side SSL context when the SNI callback switches contexts, allowing unauthenticated TLS clients to trigger the flaw remotely. The affected component handles SSL/TLS handshake negotiation when a server name indication callback modifies the security context during connection setup.

Why it matters: Operators running Python-based TLS servers with SNI callback functionality face remote code execution risk from unauthenticated clients; patching or disabling dynamic context switching in SNI callbacks should be prioritized.

Tracker inference

vulnerabilitiesResearchTracker priority: TrackCVE-2026-19553

CPython [CVE-2026-19553] SSLContext.wrap_bio() missing validation of server_hostname parameter

Source: oss-security.

A high severity vulnerability exists in CPython's ssl.SSLContext.wrap_bio() method due to missing validation of the server_hostname parameter. The incomplete article does not provide details on the impact or remediation steps.

Why it matters: Python developers using ssl.SSLContext.wrap_bio() may be exposed to potential certificate validation bypass or man-in-the-middle attacks depending on the specific validation flaw.

Tracker inference

threat intel

UAE Resists Onslaught of Iranian Cyberattacks

Source: HealthcareInfoSecurity.

The United Arab Emirates attributed its resilience against cyberattacks from the Persian Gulf region to internal capabilities, information sharing with allies, and support from hyperscalers. Government officials discussed these defensive measures at the GISEC Global conference in Dubai.

Why it matters: Organizations in the Gulf region and those doing business there should understand how nation-state actors target the UAE and what partnership models support regional defense.

Tracker inference

ai security

Webinar | Can You Account for What Your AI Agents Do With Sensitive Data?

Source: HealthcareInfoSecurity.

This is a webinar announcement about accountability and data handling in artificial intelligence (AI) agents, specifically addressing how sensitive data is managed by autonomous AI systems.

Why it matters: Security practitioners deploying AI agents need to understand data governance and audit trails to meet compliance requirements and prevent unauthorized access to sensitive information.

Tracker inference

threat intel

Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks

Source: The Hacker News.

Microsoft warned of phishing campaigns distributing a legitimate MSP360 Remote Monitoring and Management (RMM) installer disguised as meeting invitations, PDF files, software updates, and other social engineering lures. Once executed, the installer establishes remote management access on affected systems, potentially enabling follow-on attacks.

Why it matters: Organizations using MSP360 or MSPs managing customer environments should train users to scrutinize unsolicited RMM installation prompts and verify software updates through official channels, as compromised remote access can lead to full system control.

Tracker inference

See what changed in the latest update.Looking further back? Browse the daily archive, this feed's own history.

How this is computed

Stories come from the published source set, are combined when reports cover the same event, and are ordered newest first. Trending uses the last 7 Coordinated Universal Time (UTC) calendar days, while the details feed states each story's published or first-seen date.

Method reviewed on .

Glossary